NEWSRoom

Swiggy Achieves PCI DSS v4.0.1 Level 1 for the Fourth Consecutive Year, Validated by Crossbow

September 9, 2026
Date Icon

BENGALURU, India - Swiggy has been validated at Merchant Level 1, the highest tier of the Payment Card Industry Data Security Standard (PCI DSS), for the fourth consecutive year, this year against the current v4.0.1 revision. The validation was completed by Crossbow Enterprise Cybersecurity following a full on-site assessment at Swiggy's headquarters in Bengaluru.

Merchant Level 1 applies to organizations that process more than six million card transactions a year, the largest and most complex payment environments. Achieving it requires an annual on-site assessment against the full PCI DSS control set, culminating in a Report on Compliance (ROC) signed off by a Qualified Security Assessor.

Version 4.0.1 raises the bar further. It strengthens authentication and encryption requirements, expands continuous monitoring, and introduces targeted risk analysis. Together these changes move organizations away from point-in-time audits toward security that holds up every day, not just on assessment day.

At Swiggy's scale, that shift is the whole point. For a platform handling millions of transactions daily, protecting payment data is not a periodic checkbox but an operational discipline built into systems, teams and processes. Sustaining Level 1 validation across four consecutive years reflects that discipline in practice, not a one-time exercise.

Crossbow congratulates the Swiggy team on the rigour and commitment they brought to achieving Level 1 validation again this year.


About Swiggy
Founded in 2014 and headquartered in Bengaluru, Swiggy is a consumer-first technology company that operates a diversified hyperlocal commerce platform through a single unified app. Spanning food delivery, quick commerce and dining-out services, Swiggy connects millions of users with restaurant and merchant partners across more than 600 cities in India.

Contact details: pr@crossbowsec.com